CVE-2015-3246

MEDIUM(5.1)KEV

Red Hat Libuser Race Condition Vulnerability

Description

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allows local users to cause a denial of service (inconsistent file state) by causing an error during the modification. NOTE: this issue can be combined with CVE-2015-3245 to gain privileges.

KEV Information

Vendor
Red Hat
Product
Libuser
Date Added
August 26, 2026
Due Date
September 9, 2026
Required Action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS Score

Vector String
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HOpen in Calculator
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.4
Impact Score
3.6

CWEs

Affected Products

VendorProductVersion
redhatenterprise linux5.0; 6.0; 7.0
opensuseopensuse13.2
libuser projectlibuser< 0.56.13-8; >= 0.60, < 0.60-7

References

CVSS Score

5.1
MEDIUM(5.1)

EPSS Score

EPSS Score8.80%
EPSS Percentile94.9%

Dates

PublishedAugust 11, 2015
Last ModifiedAugust 27, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.